Tenda AX3 Buffer Overflow Vulnerability in AdvSetMacMtuWan Function

Vulnerability

A buffer overflow vulnerability has been identified in the Tenda AX3 router running firmware version V16.03.12.10_CN. This vulnerability arises in the 'AdvSetMacMtuWan' function, where the 'serverName' parameter is not properly validated. Attackers can exploit this oversight by sending excessively long data, leading to a stack overflow that overwrites the function's return address. Such exploitation can cause the router to crash, disrupting its normal service operations.

Impact

Exploitation of this vulnerability causes the router to crash, leading to a denial of service where the device fails to provide services correctly and persistently.

Reproduction

To reproduce this vulnerability, send a POST request to the '/goform/AdvSetMacMtuWan' endpoint. Include a 'serverName' parameter with a payload of repeated characters to exceed the buffer limit. The router will crash, demonstrating the successful exploitation of the buffer overflow.

Added: Aug 22, 2025, 4:18 PM
Updated: Aug 22, 2025, 6:49 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
5.8
remediation
7.7
relevance
0.4
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.